FB pixel

OCR Labs denies breach report details, patches vulnerability

OCR Labs denies breach report details, patches vulnerability
 

A vulnerability allegedly exposing sensitive credentials of Australian financial institutions has been closed by OCR Labs, after being discovered and disclosed by Cybernews researchers. The biometric liveness detection API used by OCR Labs is among the exposed data, according to the report.

OCR Labs takes issue with details in the report, however, telling Biometric Update that the API is used to create Liveness sessions, which are ephemeral and cannot be recalled once complete. No personally identifiable information was accessible, therefore.

“There was never a data leak or breach in any of our systems,” says Paul Warren-Tape, GM of APAC for OCR Labs, in a response statement shared with Biometric Update.

The data was made accessible through a misconfigured and publicly accessible environment file used by OCR Labs product IDKit.com, which provides bank-grade identity verification with selfie biometrics. The file included database credentials, including for access to Amazon Web Services and Simple Queue Service (SQS), along with API keys.

Australia’s Qbank, which caters mostly to government agency workers, Defence Bank, which serves the countries armed forces, and residential mortgage provider MA Money, were all affected. The UK’s Bloom Money and Admiral Money, as well as recruitment service Reed, were also impacted, according to Cybernews.

“Investigations lead by third party cyber security specialists unequivocally concluded that, at no stage, was there any threat to QBANK Member data,” Qbank said in a statement.

OCR Labs says it took all necessary steps to address the vulnerability immediately on learning of it. The company follows a vulnerability disclosure program (VDP) framework to ensure transparency and security.

The leaked data included API keys for Liveness and credit reporting agency Experian, and credentials for OCR Labs’ Engine v4, which is used for KYC checks, and therefore connects to sensitive customer data.

An internal investigation by OCR Labs shows no risk to the security of any client’s data.

“After extensive investigation, we can unquestionably confirm the discovered configuration related to invalid and placeholder credentials were for unused demo and placeholder environments. These are all non-production environments and pose no risk to the security of our client’s data or our systems,” says Warren-Tape.

He also noted that OCR Labs acknowledges the need to secure even “demo or placeholder environments with invalid credentials” as it does production environments.

The company says it is now seeking independent legal advice on the allegedly inaccurate reporting, on the advice of the Australian Cyber Security Centre.

OCR Labs was recently approved to the UK’s DIATF for right-to-work checks.

Article Topics

 |   |   | 

Latest Biometrics News

 

Precise Biometrics, Fingerprint Cards set to emerge as combined entity next week

Sweden’s corporate regulator has approved the merger between Precise Biometrics and Fingerprint Cards, completing the final step before the two…

 

OfDIA confirms commitment to DVS trust framework in annual report

A new annual report from the UK’s Office for Digital Identities and Attributes (OfDIA) refreshes its commitment to support biometrics…

 

Trust Stamp joins EU advanced semiconductor initiative for secure digital identity

Trust Stamp has been chosen for one of Europe’s most strategic technology programs. The company is joining a major EU…

 

Reken launches on-device AI platform to detect phishing and impersonation scams

After two years of development, Reken has come out of stealth with an AI security platform that can analyze communications…

 

Xcelerate and Socure win $163M Login.gov identity proofing contract

Xcelerate Solutions and its subcontractor Socure have been awarded a five-year, $163 million call order to provide identity proofing technology…

 

Belgians warned of vulnerability to fake IDs from AI, digital copies

Belgium’s federal police have sounded the alarm about AI-driven identity fraud affecting individuals across the country. The scams described in…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events